7.5
CVE-2025-56233 -
Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN flag set, Openindiana has a wide acceptable range of sequence numbers. It does not require the sequence number to exactly match the next expected sequence value, just to be withinโฆ
7.5
CVE-2025-51495 - mongoose: Integer Overflow in Mongoose's WebSocket component
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow.
6.8
CVE-2025-61659 -
bash-git-prompt 2.6.1 through 2.7.1 insecurely uses the /tmp/git-index-private$$ file, which has a predictable name.
8.2
CVE-2025-57516 -
OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.
5.3
CVE-2025-56764 -
Trivision NC-227WF firmware 5.80 (build 20141010) login mechanism reveals whether a username exists or not by returning different error messages ("Unknown user" vs. "Wrong password"), allowing an attacker to enumerate valid usernames.
8.1
CVE-2025-57483 -
A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter.
7.3
CVE-2025-57424 -
A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their profile, which executes in the browser of any user viewing it, including administrators. Due to the absence of the Httpโฆ
3.5
CVE-2025-55795 -
The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated attacker controlling a user account with a lower user ID can update their email address to that of another user with a โฆ
9.9
CVE-2025-10725 - Openshift-ai: overly permissive clusterrole allows authenticated users to escalate privileges to clโฆ
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. This allows for the complete compromise of the clustโฆ
7.8
CVE-2025-41244 - VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (Cโฆ
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability.ย A malicious local actor with non-administrative privileges having access to a VM with VMware Toolsย installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privilโฆ